U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

2026-08-26T01:23:59Z4a1285c79a5076486959330f8b9c21fc7f604c09776d35aa5789b9a9600d8506
CVE-2026-18963CVE-2026-19478CVE-2026-21962CVE-2026-61979account-takeoveractive-exploitationai-securityauthentication-bypassbackdoorclickfixcritical-infrastructuregitlabkeycloaklinuxmalwaremcpmicrosoft-365model-poisoningnpm-supply-chainoraclepasskeysphishingratrcesamlvulnerabilityweblogicwindowswordpress

What happened

The feed reports a broad set of significant cybersecurity developments, including active exploitation of critical Oracle WebLogic/HTTP Server and GitLab vulnerabilities, severe Keycloak account takeover and miniOrange SAML authentication bypass flaws, AI-agent and notebook command-execution risks, phishing-as-a-service campaigns targeting Microsoft 365, malicious npm packages, malware delivery via fake CAPTCHA pages and gaming sites, RAT and backdoor campaigns, and attacks against critical infrastructure and web servers. Multiple items involve unauthenticated remote compromise, account or data

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
4a1285c79a5076486959330f8b9c21fc7f604c09776d35aa5789b9a9600d8506
Enrichment time
2026-08-26T01:23:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches · Baitaphish